OpenAI has introduced Aardvark, an autonomous cybersecurity research agent powered by GPT-5, now available in a private beta. Designed to assist security teams, Aardvark can connect to code repositories, discover vulnerabilities, explain security issues, and help patch them using large language model (LLM)-powered reasoning and tool use. The agent was initially developed as an internal tool for OpenAI’s own developers, who found it valuable for clarifying and guiding fixes for security issues. Aardvark operates by examining codebases, understanding their objectives and design, and then scanning for vulnerabilities in both historical and newly committed code, annotating problematic sections for human review.
Unlike traditional program analysis techniques such as fuzzing or software composition analysis, Aardvark uses LLM-driven methods to analyze code behavior, develop threat models, and prioritize vulnerabilities for remediation. The tool can also sandbox vulnerabilities to test exploitability, submit proposed patches, and has demonstrated the ability to identify 92% of known and synthetic vulnerabilities in test repositories. OpenAI is offering Aardvark for free to noncommercial open source projects and has recently updated its coordinated vulnerability disclosure process to focus on broader ecosystem security rather than strict disclosure timelines.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
OpenAI announced Aardvark, a GPT-5-powered agent designed to autonomously support cybersecurity research, vulnerability management, and the detection and remediation of hidden code flaws. Multiple outlets reported the launch as a new OpenAI security and patching model intended to find and fix software bugs automatically.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcecsoonline.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcezdnet.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.